@medusajs/medusa is vulnerable to Insertion of Sensitive Information into Log File
25
Low Risk
Affected versions of the package may expose sensitive information in log files by passing the provider identity update token as a parameter instead of using a Bearer token in the authorization header. This increases the risk of token leakage. To mitigate this, the update process now requires the token in the authorization header.
You are affected if you are using a version that falls within the vulnerable range.
@medusajs/medusa is vulnerable to Insertion of Sensitive Information into Log File in versions 1.0.0 - 2.5.1.
Upgrade the @medusajs/medusa library to the patch version. This is a breaking change and is not backward compatible.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant